Junglewise Threat Intelligence

CVE-2026-56214: Capgo information disclosure in Supabase PostgREST RPC endpoints

CVE-2026-56214 · Severity: high · CVSS 7.5 · Published 2026-06-20

Technologies: Capgo. Vendors: Capgo.

Executive brief

Capgo, a platform for managing app updates, contained a security flaw that allowed unauthorized individuals to view sensitive business information. By accessing specific public-facing interfaces, an attacker could verify the existence of specific organizations and identify which ones are paying customers. This information could be used for targeted phishing attacks or competitive intelligence gathering.

Technical details

An information disclosure vulnerability exists in Capgo versions prior to 12.128.2 due to improperly secured Supabase PostgREST RPC endpoints. Specifically, the 'is_trial_org' and 'is_paying_org' endpoints can be invoked by unauthenticated attackers using a public 'sb_publishable' key. The 'is_trial_org' endpoint acts as an existence oracle by returning an integer for valid organizations and 'null' for non-existent ones, while 'is_paying_org' returns a boolean indicating billing status. This allows for large-scale organization enumeration and customer profiling. The issue was resolved in version 12.128.2 by restricting these RPCs to authenticated contexts or ensuring uniform responses.

Affected products

  • Capgo Capgo < 12.128.2

Timeline

  • 2026-03-17: advisory: Initial GitHub security advisory published
  • 2026-06-20: disclosed: CVE published to NVD dataset

References

Related threats